FCKeditor.Java Infinite Loop Denial of Service Vulnerability
BID:35709
Info
FCKeditor.Java Infinite Loop Denial of Service Vulnerability
| Bugtraq ID: | 35709 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2009 12:00AM |
| Updated: | Jul 16 2009 09:36PM |
| Credit: | FCKeditor |
| Vulnerable: |
FCKeditor FCKeditor.Java 2.4 |
| Not Vulnerable: |
FCKeditor FCKeditor.Java 2.4.2 |
Discussion
FCKeditor.Java Infinite Loop Denial of Service Vulnerability
FCKeditor.Java is prone to a remote denial-of-service vulnerability because it fails to properly handle request parameters.
Attackers can exploit this issue to cause the application to enter an infinite loop, which may cause denial-of-service conditions.
Versions prior to FCKeditor.Java 2.4.2 are vulnerable.
FCKeditor.Java is prone to a remote denial-of-service vulnerability because it fails to properly handle request parameters.
Attackers can exploit this issue to cause the application to enter an infinite loop, which may cause denial-of-service conditions.
Versions prior to FCKeditor.Java 2.4.2 are vulnerable.
Exploit / POC
FCKeditor.Java Infinite Loop Denial of Service Vulnerability
Attackers may exploit this issue via a browser.
Attackers may exploit this issue via a browser.
Solution / Fix
FCKeditor.Java Infinite Loop Denial of Service Vulnerability
Solution:
Updates are available; please see the references for details.
FCKeditor FCKeditor.Java 2.4
Solution:
Updates are available; please see the references for details.
FCKeditor FCKeditor.Java 2.4
-
FCKeditor fckeditor-java-2.4.2-bin.tar.gz
http://sourceforge.net/projects/fckeditor/files/FCKeditor.Java/fckedit or-java-2.4.2-bin.tar.gz/download
References
FCKeditor.Java Infinite Loop Denial of Service Vulnerability
References:
References:
- FCKeditor.Java Homepage (FCKeditor)
- Release Name: 2.4.2 (FCKeditor)
- Unsanitized request parameters may cause the request loop endlessly (FCKeditor)